RC RANDOM CHAOS

The Wire

Curated cybersecurity and tech news — AI-summarized, source attributed.

aiopen-source

llm-echo 0.5a0 adds thinking-block simulation for LLM 0.32a0 testing

Simon Willison shipped version 0.5a0 of llm-echo, a plugin that registers a fake "echo" model inside the LLM CLI tool. The model performs no inference — it simp

via Simon Willison ·
vulnerabilitycybersecurity

MetInfo CMS Flaw CVE-2026-29014 Under Active Exploitation for Unauthenticated RCE

A critical PHP code injection vulnerability in MetInfo CMS versions 7.9 through 8.1, tracked as CVE-2026-29014 with a CVSS score of 9.8, is being actively explo

via The Hacker News ·
cybersecuritypolicy

Middle East cyber conflict expands, with UAE emerging as a primary target

Cyber operations across the Middle East are widening in scope, and the UAE is taking a disproportionate share of the activity. The shift reflects the country's

via Dark Reading ·
aipolicy

Musk's lawyers grill OpenAI's Brockman over diary entries revealing profit motives

OpenAI president Greg Brockman took the stand in Elon Musk's lawsuit against OpenAI, where Musk's attorney Steven Molo forced him to read aloud personal journal

via Ars Technica ·
identitycybersecurity

OAuth Tokens Are the Unwatched Back Door: Drift Breach Shows the Cost

OAuth grants issued to AI tools, automation platforms, and productivity apps don't expire, don't reset when passwords change, and rarely sit under any centraliz

via The Hacker News ·
aipolicy

Pennsylvania sues Character.AI over chatbot posing as licensed psychiatrist

Pennsylvania's Department of State and Board of Medicine have sued Character.AI, alleging the platform hosts chatbot characters that impersonate licensed medica

via Ars Technica ·
malwaresupply-chain

Quasar Linux implant hunts developer credentials with eBPF rootkit and PAM backdoors

Trend Micro has documented a previously unseen Linux malware kit, Quasar Linux (QLNX), built specifically to compromise developer and DevOps workstations intera

via BleepingComputer ·
policytech-culture

RFK Jr. targets SSRI prescribing with debunked heroin-comparison claims

Health Secretary Robert F. Kennedy Jr. used a Make America Healthy Again Institute event to announce federal initiatives aimed at reducing antidepressant prescr

via Ars Technica ·
cybersecuritysupply-chain

ShinyHunters claims 280M-record theft from Instructure Canvas across 8,800 institutions

The ShinyHunters extortion crew is taking credit for last week's Instructure breach, claiming exfiltration of roughly 280 million records spanning students, tea

via BleepingComputer ·
cybersecurityidentity

ShinyHunters' Vishing Spree Shows Social Engineering Still Beats Tech Defenses

Troy Hunt's latest weekly update zeroes in on ShinyHunters, a loose crew of young threat actors punching well above their weight against major brands. Their acc

via Troy Hunt ·
open-sourceprivacy

Star Labs StarFighter 16: Linux laptop with removable webcam, kill switch, open firmware

Star Labs has unveiled the StarFighter 16, a 16-inch Linux performance laptop targeting privacy-conscious technical users. Configurations span Intel Core Ultra

via Hacker News ·
cybersecurityvulnerability

Taiwan student halts high-speed trains by spoofing 19-year-old TETRA signals

A 23-year-old in Taiwan, identified by his surname Lin, brought four Taiwan High Speed Rail trains to an emergency stop for 48 minutes on April 5 by transmittin

via BleepingComputer ·